Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

NaCl gets >2x slowdown in some cases as the restrictions enforced by proof carrying code gets in the way (dynamic code generation, instruction set filtering).

There are faster more efficient ways of isolating a process - and better provided at an OS level (see Xax for instance).

PCC makes sense where you need to inline externally delivered code in a process - inline driver filters and so on.



Right, NaCl early work had beautiful in-process SFI. But that went away soon, and it was OOP-isolated on top. I never got a straight story as to why.

/be




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: